4.1301 Policy.

(a) Agencies must follow FIPS PUB Number 201 and the associated OMB implementation guidance for personal identity verification for all affected contractor and subcontractor personnel when contract performance requires contractors to have routine physical access to a Federally-controlled facility and/or routine access to a Federally-controlled information system.

(b) Agencies must include their implementation of FIPS PUB 201 and OMB Guidance M-05-24 in solicitations and contracts that require the contractor to have routine physical access to a Federally-controlled facility and/or routine access to a Federally-controlled information system.

(c) Agencies must designate an official responsible for verifying contractor employee personal identity.

(a) In order to comply with FIPS PUB 201, agencies must purchase only approved personal identity verification products and services.

(b) Agencies may acquire the approved products and services from the GSA, Federal Supply Schedule 70, Special Item Number (SIN) 132-62, HSPD-12 Product and Service Components, in accordance with ordering procedures outlined in FAR Subpart 8.4.

(c) When acquiring personal identity verification products and services not using the process in paragraph (b) of this section, agencies must ensure that the applicable products and services are approved as compliant with FIPS PUB 201 including—

4.1303 Contract clause.

The contracting officer shall insert the clause at 52.204-9, Personal Identity Verification of Contractor Personnel, in solicitations and contracts when contract performance requires contractors to have routine physical access to a Federally-controlled facility and/or routine access to a Federally-controlled information system. The clause shall not be used when contractors require only intermittent access to Federally-controlled facilities.